The server implementation of the EAP-MSCHAPv2 protocol in the eap-mschapv2 plugin in strongSwan 4.2.12 through 5.x before 5.3.4 does not properly validate local state, which allows remote attackers to bypass authentication via an empty Success message in response to an initial Challenge message.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade strongswan | Aug 30, 2017 | Nov 18, 2015 |
| Debian | — | Upgrade strongswan | Nov 18, 2015 | Nov 16, 2015 |
| Freebsd | — | Upgrade strongswan | Dec 10, 2025 | Nov 16, 2015 |
| Huawei Euleros 2_0_sp2 | — | Upgrade strongimcv | Feb 22, 2021 | Nov 18, 2015 |
| Suse | — | Upgrade strongswan-hmacUpgrade strongswan-libs0Upgrade strongswanUpgrade strongswan-ipsecUpgrade strongswan-docUpgrade strongswan-nm | Dec 18, 2015 | Nov 18, 2015 |
| Ubuntu | — | Upgrade strongswan-plugin-eap-mschapv2 | Nov 23, 2015 | Nov 16, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub